Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pf8v-w5wh-93wr

Опубликовано: 28 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device.

This vulnerability is due to insufficient security restrictions when executing application arguments from the Bash shell. An attacker with privileges to access the Bash shell could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to create new users with the privileges of network-admin.

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device.

This vulnerability is due to insufficient security restrictions when executing application arguments from the Bash shell. An attacker with privileges to access the Bash shell could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to create new users with the privileges of network-admin.

EPSS

Процентиль: 13%
0.00044
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.7
nvd
больше 1 года назад

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on an affected device. This vulnerability is due to insufficient security restrictions when executing application arguments from the Bash shell. An attacker with privileges to access the Bash shell could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to create new users with the privileges of network-admin.

CVSS3: 6.7
fstec
больше 1 года назад

Уязвимость командной оболочки Bash операционной системы Cisco NX-OS коммутаторов Cisco Nexus 3000 и Nexus 9000, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 13%
0.00044
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-862